CVE-2025-5777HIGH 7.5CISA KEVEPSS p100.0%

CVE-2025-5777Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Citrix / NetScaler ADC and Gateway

Description

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

Scoring

CVSS 3.17.5 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS99.90% probability of exploitation · percentile 100.0% · 2026-06-15T12:03:41Z
Published2025-06-17
Last modified2025-10-30

CISA KEV entry

Added to KEV: 2025-07-10

Underlying weaknesses· 3

CWE-125CWE-908CWE-457

References

  1. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420
  2. https://citrixbleed.com
  3. https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/
  4. https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/
  5. https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/
  6. https://www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/
  7. https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/
  8. https://doublepulsar.com/citrixbleed-2-exploitation-started-mid-june-how-to-spot-it-f3106392aa71

3

TypeTargetConfidenceTier
WeaknessOut-of-bounds Readcwe-1250%live
WeaknessUse of Uninitialized Variablecwe-4570%live
WeaknessUse of Uninitialized Resourcecwe-9080%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryCitrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerabilitykev-cve-2025-57770%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Citrix NetScaler Out-of-Bounds Read Vulnerability
CVE
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
CVE
Citrix NetScaler Memory Overflow Vulnerability
CVE
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
CVE
CVE-2025-7776
CVE
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.